Fun

News Feed - 2023-09-11 10:09:19

Brayden Lindrea7 hours agoLido assures LDO, stETH tokens remain safe despite flaw in token contractThe “fake deposit” attack enables bad actors to execute a transfer where the requested value is larger than what the user actually owns.2581 Total views21 Total sharesListen to article 0:00NewsJoin us on social networksEthereum staking protocol Lido Finance has assured both Lido DAO (LDO) and staked-Ether (stETH) tokens remain safe despite hackers allegedly exploiting a known security flaw in LDO’s token contract.


Lido didn’t confirm any exploits, but acknowledged the security flaw was known and reassured LDO and stETH funds remain safe in response to a Sept. 10 post by blockchain security firm SlowMist.


SlowMist said LDO’s flawed token contract allows bad actors to facilitate “fake deposit” attacks on exchanges because LDO’s token contract enables users to execute transactions even where they don’t have sufficient funds. This code deviates from the Ethereum Request for Comment 20 (ERC-20) token standard, according to SlowMist.


However, Lido Finance argued the flaw is built into all ERC-20 tokens — not just Lido’s LDO token:This behaviour is expected and conforms to the ERC20 token standard (see tweet below). Both LDO and stETH (and Lido governance) remain safe.

Lido token integration guides will be updated with LDO specifics to make this more visible shortly.— Lido (@LidoFinance) September 10, 2023


SlowMist said the “fake deposit” attacks came from LDO’s token contract executing transfers where the value is larger than what the user actually owns, triggering a false return as opposed to reverting the transaction. While the firm said Lido’s token contract has recently been exploited via this attack, no on-chain evidence was provided.


Cointelegraph reached out to SlowMist for comment but did not receive an immediate response.


Meanwhile, on-chain analyst “Hercules” explained on Sept. 10 that the security flaw may not be picked up by cryptocurrency exchanges.


SlowMist recommends LDO holders to also check the return values of the token contract transfers in addition to the success or failure of a transaction.


The blockchain security firm concluded that token contract implementations and behaviors vary by project and to conduct comprehensive testing before integrating any new tokens.


Related:Ethereum staking services agree to 22% limit of all validators


However, Lido highlighted in the official Ethereum Improvement Proposal document — co-authored by Vitalik Buterin in November 2015 — that both the “transfer” and “transferFrom” functions must return the transfer status and are only recommended to revert a transaction in exceptional cases.ERC20 token standard: https://t.co/YlrS1ZN6Fd

1) Both transfer and transferFrom are required to return transfer status and are only recommended to revert a tx in exceptional cases.

2) The standard says that a caller is obliged to check the return status (see 'Token methods'). pic.twitter.com/6KTcIyxo2F— Lido (@LidoFinance) September 10, 2023


To resolve the security flaw, Lido confirmed that the LDO token integration guides will soon be updated.


Collect this article as an NFTto preserve this moment in history and show your support for independent journalism in the crypto space.


Magazine:DeFi Dad, Hall of Flame: Ethereum is ‘woefully undervalued’ but growing more powerful# Altcoin# Security# Ethereum# Hackers# DAO# ERC-20# DeFi# Staking# Lido DAOAdd reactionAdd reactionRead moreHow to actually spend your Bitcoin, ExplainedCrypto VC: Risk and investment strategies with Shima CapitalHuman vs. AI: Who is better at crypto investing?

News Feed

Wind-Breaking NFTs: Reality Star Who Made $200K Selling Farts in Mason Jars Launches NFT Collection
Wind-Breaking NFTs: Reality Star Who Made $200K Selling Farts in Mason Jars Launches NFT Collection Just recently the reality star, American Youtuber, and Tiktoker Stephanie Matto
CoinEx Looks Forward to Celebrating RLWC2021’s Finalists
CoinEx Looks Forward to Celebrating RLWC2021’s Finalists press release PRESS RELEASE.As the exclusive cryptocurrency trading platform partner of the Rugby League World Cup 2021 (R
Peter Schiff Claims Grayscale Will Sell BTC to Fund DCG’s Acquisition of GBTC Shares Rebuffed
Peter Schiff Claims Grayscale Will Sell BTC to Fund DCG"s Acquisition of GBTC Shares Rebuffed Gold bug and bitcoin opponent, Peter Schiff has alleged that the Di
Ethereum Price Breaks Above Massive Triangle – Next Target: $10,000
Este artículo también está disponible en español. Recent price action has seen the Ethereum price breaking above the $4,000 price level again to drive euphoria among cryp
Smart Contract Token Market Soars to $332 Billion; Defi Value Reaches High Not Seen Since FTX Collapse
Smart Contract Token Market Soars to $332 Billion; Defi Value Reaches High Not Seen Since FTX Collapse The smart contract token economy rose 5.6% against the U.S. dollar on Thursda
45 Older-Generation Bitcoin Miners Are Unprofitable After the Reward Halving
45 Older-Generation Bitcoin Miners Are Unprofitable After the Reward HalvingOn May 11, the Bitcoin network experienced its third block reward halving, which had chopped the 12.5 BTC
How US job market slump could boost Bitcoin prices
Zoltan Vardai10 hours agoHow US job market slump could boost Bitcoin pricesBitcoin could rise due to a weaker job market, but Bitcoin ETFs are on track to their third consecutive week of net negative outflows.5257 Total
3 reasons why Pepe poised for another 70% jump by July
Yashu Gola12 hours ago3 reasons why Pepe poised for another 70% jump by JulyPEPE’s rising wedge pattern, rising whale accumulation and increasing rate cut bets could boost the memecoin’s price in June.1511 Total view
India’s Tax Authority Asks Crypto Exchanges for Details of Coins Traded on Their Platforms
India"s Tax Authority Asks Crypto Exchanges for Details of Coins Traded on Their Platforms India’s tax authority has reportedly asked major cryptocurrency exchanges in the co
Trava Finance Is a Groundbreaking Protocol That Lets You Create Lending Pools to Start a Lending Business
Trava Finance Is a Groundbreaking Protocol That Lets You Create Lending Pools to Start a Lending Business sponsored Trava is the next generation of Lending Protocols, employing an i
Bitcoin price tied to US dollar performance, not politics, custodian says
Ana Paula Pereira3 hours agoBitcoin price tied to US dollar performance, not politics, custodian saysMarket expectations of a weakening US dollar may be behind Bitcoin’s recent surge, overshadowing election speculation
USDC Sees Native Launch on Avalanche
USDC Sees Native Launch on Avalanche USDC, the second leading stablecoin by market cap, has been launched on the Avalanche blockchain as a native token. Previously, users wanting t